Virtual private networks (vpn) access based on client workstation security compliance
Abstract
Techniques for virtual private network (VPN) access, which is based on client workstation security compliance, are provided. When a user successfully logs into a secure network, client integrity checks are processed on a client workstation of the user to gather configuration information related to a processing environment of the client workstation. Metrics associated with the client integrity checks are compared with security policy and an assigned security access level is set for the user during a VPN session. Traffic policy is then enforced against the VPN session by configuring attributes of the VPN session.
Claims
exact text as granted — not AI-modified1 . A machine-implemented method, comprising:
detecting a successful login of a user into a secure network and originating from a client workstation; performing a client integrity check against a processing environment of the client workstation; assigning a security access level to the user and the client workstation for a virtual private network (VPN) session with resources of the secure network in response to the client integrity check; and setting a traffic policy for communication between the user and the resources during the VPN session in response to the security access level.
2 . The method of claim 1 , wherein detecting further includes dynamically downloading and installing a client integrity service on the client workstation in response to the successful login of the user to the secure network.
3 . The method of claim 2 , wherein performing further includes processing the client integrity service on the client workstation to perform the client integrity check.
4 . The method of claim 3 , wherein performing further includes receiving back from the client integrity service configuration information for the client workstation, wherein the configuration information captured by the client integrity service is defined by an administrator policy that accompanies the client integrity service when it is downloaded to the client workstation.
5 . The method of claim 4 , wherein receiving further includes identifying in the configuration information one or more of the following conditions: whether a particular software application is present on the client workstation, whether a particular file or dataset is present on the client workstation, whether a particular registry key is set on the client workstation, whether a particular version of a file is present on the client workstation, whether a particular version of a software application is present on the client workstation, whether a particular version of an operating system is running on the client workstation, and a listing of processes that are currently running on the client workstation.
6 . The method of claim 5 , wherein assigning further includes resolving a particular security access level in response to the configuration information and a security policy.
7 . The method of claim 1 , wherein setting further includes configuring attributes for the VPN session to enforce the security access level, wherein the attributes include one or more of the following: a network destination address, a destination mask, a communication port number, a user-defined access role, and a processing action to take.
8 . A machine-implemented method, comprising:
acquiring a client integrity checking (CIC) policy for a user that logs into a secure network; pushing the CIC policy to a client workstation that the user logs into the secure network with for enforcement on the client workstation; receiving metrics back from the client workstation in response to the enforcement of the CIC policy, wherein the CIC policy defines the metrics to capture from the client workstation; evaluating the metrics in response to security policies to select a particular traffic policy for the user; and setting the traffic policy and establishing a secure socket layer (SSL) virtual private network (VPN) session for the user to interact with the secure network.
9 . The method of claim 8 , wherein acquiring further includes one or more of the following:
accessing a policy repository using an identifier for the user to acquire the CIC policy; and interacting with an administrator that defines the CIC policy.
10 . The method of claim 8 , wherein pushing further includes processing one or more security compliance checks on the client workstation as defined in the CIC policy, wherein each security compliance check results in one or more the metrics being captured.
11 . The method of claim 8 , wherein evaluating further includes identifying three security policies: one associated with a first security access level, another associated with a second security access level, and a third associated with a third security access level, wherein the second security access level includes the first security access level, and wherein the third security access level includes the first and second security access levels.
12 . The method of claim 11 , wherein setting further includes permitting email and instant messaging access for the first security access level, permitting the first security level access and file transfer protocol and telnet services for the second security access level, and permitting the first and second security access levels and complete access to the security network for the third security access level.
13 . The method of claim 8 , wherein setting further includes providing access to a single resource during the SSL VPN session when a threshold amount of metrics are provided.
14 . The method of claim 8 , wherein setting further includes permitting an administrator to manually override the set traffic policy to a different traffic policy.
15 . A machine-implemented method, comprising:
a client agent implemented in a machine-accessible and computer-readable medium and to process on client workstation of a network; and a traffic policy enforcer implemented in a machine-accessible and computer-readable medium and to process on a server machine of the network; wherein the client agent is dynamically downloaded and initiated on the client workstation from the server machine when a user first attempts to establish a virtual private network (VPN) session with secure resources of the network, and wherein when the user successfully logs into the network the traffic policy enforcer receives metrics from the client agent regarding client integrity checks for a processing environment of the client workstation of the user and in response thereto the traffic policy enforcer sets a security access level for the user during the VPN session.
16 . The system of claim 15 , wherein the metrics gathered by the client agent are preconfigured in the client agent in response to an administrative policy.
17 . The system of claim 15 , wherein the metrics identify a version and a type of operating system being used on the client workstation and identifies a version and a type of virus scan software executing on the client workstation.
18 . The system of claim 17 , wherein the metrics further identify whether a presence and a version of particular software services exists on the client workstation.
19 . The system of claim 15 , wherein the traffic policy enforcer ensures the security access level by configuring attributes for the VPN session that include a network destination address, a destination mask, a communication port number, a user-defined access role, and a processing action to take for each interaction attempted by the user during the VPN session.
20 . The system of claim 15 , wherein the security access level is cumulative so that a higher value assigned to the security access level includes access rights permitted by lower security access levels.
21 . A machine-implemented system, comprising:
a virtual private network (VPN) establishment service implemented in a machine-accessible and computer-readable medium and processing on a server machine of a network; and a client integrity checking (CIC) service implemented in a machine-accessible and computer-readable medium and to process on the server machine and on a client machine of the network; wherein the VPN establishment service informs the CIC service when a user successfully logs into the network, and wherein a server portion of the CIC service pushes a CIC policy to a client portion of the CIC service, the client portion gathers metrics in compliance with the CIC policy and reports the metrics back to the server portion, in response to the metrics the server portion configures traffic policies for a VPN session of the user for subsequent interaction with secure resources of the server machine, and wherein the traffic policies enforce an assigned security access level that the user is to have during the VPN session.
22 . The system of claim 21 , wherein the server portion identifies the CIC policy in response to an identity assigned to the user.
23 . The system of claim 21 , wherein the metrics identify information for a configuration of a processing environment of the client machine of the user.
24 . The system of claim 21 , wherein the CIC policy is predefined by an administrator and acquired from a policy repository.Join the waitlist — get patent alerts
Track US2009254967A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.